Zenity Labs Uncovers SalesBleed, 3 Salesforce Agentforce Flaws Enabling Zero-Click CRM Data Theft and AI Agent Impersonation

Zenity Labs today disclosed SalesBleed, a set of three security vulnerabilities in Salesforce Agentforce that could allow a single untrusted lead to hijack trusted Agentforce agents, silently exfiltrate sensitive CRM data and turn an enterprise agent into a vehicle for delivering elaborate phishing attacks.

Two of the vulnerabilities enable zero-click data exfiltration, allowing sensitive Salesforce data to be transmitted to attacker-controlled infrastructure without requiring an employee to click or approve anything. The third allows attackers to weaponize the trusted identity of an Agentforce-connected Slack agent to distribute phishing messages to employees from inside the enterprise.

Zenity Labs found multiple weaknesses in Trusted URLs, the Salesforce security mechanism designed to prevent Agentforce from displaying URLs and images from untrusted sources. The researchers demonstrated that those weaknesses could be abused to send sensitive data to unapproved destinations. The research also uncovered a separate flaw in the Agentforce-Slack integration that allowed the trusted identity of an enterprise AI agent to be abused for phishing.

Zenity Labs responsibly disclosed the findings to Salesforce, which worked with the researchers to investigate and remediate the reported issues.

“This isn’t one clever bypass or a single misconfiguration. We found multiple ways to break through the security boundary designed to stop Agentforce from sending enterprise data to unapproved destinations,” said Michael Bargury, co-founder and CTO of Zenity. “Hard boundaries remain one of the strongest tools we have for containing AI agents, but they are still software. When those controls fail, we are left with a privileged access agent with high autonomy and no bounds.”

One Public Form Can Start the Attack

One attack chain begins with nothing more than a Web-to-Lead form. Web-to-Lead is Salesforce’s official mechanism for collecting leads and creates a direct path for outside information to enter the Salesforce CRM. As Zenity Labs demonstrated at Black Hat 2025, when Agentforce processes that information, the same pathway can become an attack vector. Attackers can plant malicious instructions in a Web-to-Lead submission that remain dormant until an employee later asks an Agentforce agent an ordinary question about leads. Once the agent processes the poisoned lead, the hidden instructions can hijack its behavior, causing it to exfiltrate sensitive Salesforce data or take other attacker-directed actions while returning what appears to be a normal response to the employee.

3 Vulnerabilities Identified

1. Zero-click CRM data exfiltration

Agentforce reported that the content had been blocked by the organization’s security policies, even though the sensitive CRM data had already been transmitted to the attacker-controlled server.

Trusted URLs are designed to restrict the external destinations Agentforce can access and redact links or images pointing to unapproved domains. Zenity Labs found multiple weaknesses in the control, including top-level domains the mechanism failed to recognize and character sequences that interfered with how URLs were parsed. Those weaknesses allowed malicious instructions to cause Agentforce to query Salesforce records and embed the retrieved information in image requests to an attacker-controlled server.

When the response renders, the image requests automatically transmit the embedded CRM data, with no click or additional action from the employee.

The attack is not limited to a particular CRM field. Customer deal sizes served as one example, but other CRM data available under the user’s permissions could also be exfiltrated, including customer and prospect records, contact information, pricing, contracts and other sensitive business information.

2. Zero-click data exfiltration through Slack

The second vulnerability uses Slack’s URL unfurling functionality to exfiltrate Salesforce data without user interaction. Slack automatically retrieves information from links to generate previews, and specially constructed links can cause Slack to initiate requests that carry CRM data to attacker-controlled infrastructure as soon as the links appear.

The same poisoned Web-to-Lead entry point can trigger this attack when an employee later interacts with the Salesforce agent via Slack. No malicious link needs to be clicked for the CRM data to leave the environment. The two zero-click vulnerabilities use different exploitation techniques but reach the same result. Sensitive Salesforce data can be transmitted outside the organization despite a security control intended to prevent communication with untrusted destinations.

3. Trusted AI agent impersonation and phishing

The third vulnerability involves Agentforce’s integration with Slack. Agentforce agents can join channels, read messages and send messages when prompted. Zenity Labs found that the integration allowed an agent to send messages to different channels without reliably identifying the user who initiated the action. An insider could exploit the flaw to post phishing messages under the trusted agent’s identity while remaining anonymous.

An external attacker could also achieve a similar result through indirect prompt injection. Malicious instructions planted in Web-to-Lead could cause the agent to post phishing messages across Slack threads once an employee processed the poisoned lead. The attack effectively turns an organization’s own AI agent into a social-engineering vehicle.

Employees receive a message from a trusted system already operating inside their workplace rather than from an unfamiliar outside sender. Users who follow the phishing link and surrender their credentials could give attackers access to email, Slack, source code repositories and other enterprise applications available through the compromised identity.

Why the Findings Matter

For enterprises deploying AI agents, the concern is not just what the agent can access, but how well the controls designed to contain it actually work. Trusted URLs are intended to act as a hard security boundary between Agentforce and unapproved external destinations. Zenity Labs found multiple ways to bypass that control and expose sensitive data.

“We need to think beyond whether an agent has guardrails and ask what happens when those guardrails are bypassed,” Bargury said. “Security teams need layered visibility into what agents access, which tools they invoke and what actions they take. Even with limited access and hard defense mechanisms in place, close monitoring remains essential. As the threat presented by AI agents becomes more autonomous, a single design flaw can lead to very unexpected consequences.”

Responsible Disclosure

The findings were disclosed to Salesforce on June 1, 2026. Salesforce responded quickly and worked directly with the research team to investigate the issues, addressing the specific Trusted URLs bypasses reported by Zenity Labs within approximately two weeks. The attribution issue identified in the Slack research was also remediated. Zenity Labs thanks the Salesforce team for its open and prompt response.

Research Availability

Zenity Labs published technical research detailing the findings, including:

About Zenity

Zenity is the first security and governance platform purpose-built for agents spanning SaaS, homegrown platforms (Cloud) and end user devices (Endpoint). Trusted by Fortune 500 enterprises, Zenity helps security teams confidently adopt AI by delivering defense in depth with full-lifecycle coverage, from agent discovery and posture management to real-time detection, inline prevention and response. With an agent-centric approach that prioritizes how agents behave, what they access and which tools they invoke, Zenity eliminates blind spots and enforces consistent policy and controls across environments so organizations can innovate with AI without compromising security. Learn more at www.zenity.io.

Media gallery